CVE Vulnerabilities

CVE-2014-5400

Password in Configuration File

Published: Apr 03, 2015 | Modified: Nov 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a file.

Weakness

The product stores a password in a configuration file that might be accessible to actors who do not know the password.

Affected Software

NameVendorStart VersionEnd Version
MednetHospira*5.8 (including)

Potential Mitigations

References